#9
The Hacker News
general
May 01, 2026 at 09:43 UTC
Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft
By [email protected] (The Hacker News)
AI Summary
The GitHub account 'BufferZoneCorp' published malicious Ruby gems and Go modules targeting CI pipelines for credential theft, GitHub Actions tampering, and SSH persistence. The supply chain attack uses sleeper packages to subsequently deliver malicious payloads in development environments.
Relevance score: 72.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →